AttendFlow

Privacy Policy

Last updated: 28 August 2026

This policy explains what personal data AttendFlow handles, why, on what basis, and what you can do about it. It is written for three different readers: an employer running a workspace, a person whose attendance is recorded in one, and a partner in our referral programme.

Infi-Tech Inc of P.O. Box 1286, Lilongwe, Malawi provides the service. Our processing is subject to the Malawi Data Protection Act, 2024.

Words that begin with a capital letter and are not defined here carry the meaning given to them in our Terms of Service.

  1. 1.Words used here

    A handful of terms carry specific meanings in data-protection law, and the rest of this policy depends on them.

    Personal data
    Any information relating to an identified or identifiable living person. A name, an attendance record, the coordinates of a check-in and a face template are all personal data.
    Data subject
    The person the data is about.
    Controller
    Whoever decides why and how personal data is processed. The decisions, and the responsibility for them, sit with the controller.
    Processor
    Whoever processes personal data on a controller's instructions, without deciding the purpose for themselves.
    Sub-processor
    A third party we engage to process data on our behalf in order to run the service — hosting, storage, backups, email delivery, payments.
    Biometric data
    Data resulting from technical processing of a person's physical characteristics that allows or confirms their unique identification. In this service that means the face template used for attendance verification, and nothing else.
    Processing
    Anything done with personal data — collecting, storing, using, disclosing, altering, erasing.
  2. 2.Two roles, and which one applies to you

    We handle personal data in two capacities, and almost everything in this policy follows from which one applies.

    As a processor, for Customer Data. When an employer records its people in the service, the employer is the controller: it decides who is recorded, what is recorded, which features are switched on, and how long records are kept. We process that data on the employer's instructions in order to provide the service.

    As a controller, for Account Data. When you hold an account with us, we decide how your account information, sessions and security events are handled, because they exist to run the service itself rather than at any employer's direction.

    This matters the moment you want to exercise a right. If the request is about records your employer holds, it goes to your employer. If it is about your account with us, it comes to us. Clause 14 says how.

    For a Partner we are the controller throughout: the relationship is between the Partner and us, and no employer is involved in it.

  3. 3.What we handle

    Grouped by what it is for, rather than by where it happens to be stored.

    • Account Data — name, email address, phone number, password (stored only as a hash, never in a form we can read), sessions, and the devices and addresses a session was used from.
    • Employee Records — whatever the employer chooses to record: identity, contact details, employment type, branch, department, team, job title, compensation where entered, and documents attached to a person.
    • Attendance Data — check-ins and check-outs and their timestamps, the branch or office location recorded against them, corrections and who made them, leave and absence, and where the employer enables it the coordinates and device of a scan.
    • Verification evidence — where face verification is enabled and consented to, the face template and the outcome of each comparison. Not the images: see clause 6.
    • Billing data — subscriptions, invoices, payments, and the record of what was charged and why. We do not store full card numbers.
    • Partner data — referral codes, attributions, commission and ledger entries, wallet balances, withdrawal requests, and the payout destination a Partner nominates.
    • Technical and security data — request logs, audit entries recording who did what to which record, sign-in attempts, and errors.
  4. 4.Why we process it, and on what basis

    For Account Data, Partner data and billing, we process in order to perform our contract with you, to comply with legal obligations such as keeping financial records, and for our legitimate interest in keeping the service secure and working.

    For Employee Records and Attendance Data the basis is the employer's to establish, not ours — usually performance of the employment contract, a legal obligation, or the employer's legitimate interests. We process it on their instructions.

    For biometric data we rely on explicit consent from the individual, and on nothing else. See clause 6.

    We do not use anyone's personal data for advertising, we do not sell it, and we do not share it with data brokers.

  5. 5.Location data

    Location capture is optional and off unless an employer enables it. Where it is on, the service records the coordinates at which a scan was made, so a check-in can be checked against a branch or office location.

    A coordinate is recorded at the moment of a scan and at no other time. The service does not track a device continuously, does not record location between scans, and has no background location collection.

    An employer that enables it must tell its people that it has, and why. That obligation is the employer's, because the employer is the controller of that data.

  6. 6.Face verification and biometric data

    Where an employer enables face verification, the service can confirm that an attendance scan was made by the person it claims. This is the most sensitive processing the product performs and it is treated accordingly.

    It runs on explicit consent. Consent must be informed, freely given, specific and withdrawable, and it is recorded. A person who declines or withdraws must be given a non-biometric way to record attendance, and the employer must provide one. Withdrawal takes effect going forward and triggers erasure under clause 10.

    Nothing leaves our infrastructure. Detection, liveness and recognition all run in a service we host ourselves, using openly licensed models. No face image, template or embedding is sent to any third-party biometric provider, because there is no third-party biometric provider.

    Camera frames are never stored. What is retained is a mathematical template and the outcome of a comparison — not a photograph of anybody's face.

    Face verification is an automated check that decides whether a scan is accepted. It is not used to make employment decisions on its own, the employer must keep a non-biometric route available, and a rejected scan can be put right by a person through the ordinary corrections process.

  7. 7.Cookies and what is stored in your browser

    There are no advertising cookies, no analytics cookies, and no third-party tracking of any kind in this product. No Google Analytics, no advertising pixel, no session recorder.

    What is stored falls into two groups:

    • A session cookie, so that you stay signed in. It is strictly necessary — without it the service cannot tell one signed-in person from another.
    • Preferences kept in your browser's local storage, which never reach us: whether the sidebar is collapsed, which table columns you chose, your saved views, your recent searches, and a local note of exports you asked for. Clearing your browser data removes them and costs you nothing else.
  8. 8.Who else sees it

    Personal data reaches a third party in four circumstances and no others. Where we are compelled to disclose, we will tell the affected Customer unless we are forbidden from doing so.

    • Sub-processors that run the service — hosting, database, storage, backups and email delivery. They act on our instructions and may not use the data for their own purposes.
    • Payment providers, when a Customer pays an invoice or a Partner is paid out. They receive what the payment requires and no more.
    • Where the law requires it, or to establish or defend a legal claim.
    • On a change of control, if our business is transferred — in which case the buyer is bound by this policy until it lawfully replaces it.
  9. 9.Where it is processed

    The region a deployment processes data in is declared as part of that deployment's configuration. Where biometrics are enabled the application refuses to start unless a region has been declared — deliberately, because a default would let a deployment claim a residency nobody chose.

    A declared region is a statement, not an audit. We are completing the evidence behind it — provider records for every component that touches personal data, including backups, replicas and logs — and we will name our sub-processors and their regions here once that record is complete. We would rather write that than imply a verification we have not finished.

    If your organization needs a residency commitment in writing before adopting the service, ask us and we will tell you exactly what we can evidence today.

  10. 10.How long it is kept

    Employee Records and Attendance Data are kept for as long as the employer keeps them. Retention is the employer's decision and deletion within a workspace is theirs to perform.

    Account Data is kept while the account exists. After an Organization is terminated, Customer Data stays available for export for thirty days and may then be deleted.

    Biometric templates are erased when consent stops permitting them — on withdrawal, on removal of the Face ID, when the employee record is deleted, or when the configured retention period elapses. A recurring process performs this, and it records a template as erased only when destruction is confirmed; an unconfirmed erasure stays outstanding and is escalated rather than reported as done.

    Financial and audit records — invoices, payments, ledger entries and audit logs — are kept for as long as the law requires and are not deleted on request. A ledger that can be edited is not a ledger.

    Backups are the honest exception. Data erased from the live system may persist in encrypted backups until those backups age out on their ordinary cycle. We do not restore a backup in order to reinstate data somebody asked us to erase.

  11. 11.How it is protected

    Each Organization is a separate tenant, and the separation is enforced in the database itself — so a request made in one Organization's context cannot read another's rows even if the application above it is wrong.

    Access within an Organization is governed by roles and permissions the employer configures. Passwords are stored only as hashes. Data is encrypted in transit and at rest. Security-relevant actions are written to an audit trail recording who did what to which record.

    Access to production data is restricted to the people who need it, and is logged.

  12. 12.If something goes wrong

    No system is perfectly secure. If a breach affects personal data we hold, we will notify the affected Customer without undue delay — with what we know, what we are doing about it, and what they may need to do, including any notification the employer owes its own people or the authority.

    If you believe you have found a vulnerability, tell us at info@infi-tech.net and give us a reasonable opportunity to fix it before disclosing it publicly. We will not pursue anybody who reports in good faith and does not access data beyond what is needed to demonstrate the problem.

  13. 13.Your rights

    Subject to the Malawi Data Protection Act, 2024 and to any exceptions it provides, you may:

    • Ask what personal data is held about you, and receive a copy of it.
    • Have inaccurate data corrected.
    • Have data erased where there is no longer a basis to keep it.
    • Object to processing, or ask that it be restricted while a dispute is resolved.
    • Receive data you provided in a portable form.
    • Withdraw consent at any time where processing rests on consent — which for biometric data means the processing stops and the template is erased.
    • Complain to the data protection authority designated under the Act.
  14. 14.How to exercise them

    If your request concerns records your employer holds about you — your attendance, your leave, your employee record — send it to your employer. They are the controller and the decision is theirs. We will help them answer it, but we may not act on those records without their instruction: answering directly would mean disclosing an employer's data to somebody we cannot verify has a right to it.

    If your request concerns your own account with us, or you are a Partner, write to info@infi-tech.net. We will respond within the period the Act allows, and we may need to verify who you are first.

    You do not have to come to us before complaining to the authority. We would rather you told us first, so that we can put it right.

  15. 15.Children

    The service is not directed at children, and holding an account requires you to be at least 18. Where an employer lawfully engages someone below the age of majority and records them, the employer is responsible for the additional protections the law attaches to a child's data.

  16. 16.Changes to this policy

    We may change this policy. The date at the top records when it was last changed.

    For a change that materially affects how we handle personal data, we will give notice to the registered email address of each affected Customer before it takes effect.

  17. 17.Contact

    Infi-Tech Inc · P.O. Box 1286, Lilongwe, Malawi

    Email: info@infi-tech.net · Telephone: +265 993 585 213

    Privacy questions, access requests and vulnerability reports all go to that address.

This document describes how AttendFlow operates and the basis on which it is offered. It is provided for information and does not constitute legal advice. If any part of it conflicts with a signed agreement between you and Infi-Tech Inc, that agreement prevails.